User called “internet”
-
@Phonix66 is this some pfsense you took over? As already mentioned, I am not aware of any package that would create such a user, nor have I ever seen a package create a user that would show up in the user manager gui.. As @Gertjan mentions some users can be created to run packages under - but have never seen one create one that would be listed in pfsense gui.
If you took this over - someone else might of created that for some use.. What permissions did it have in the gui if not a member of admin group.
Have you installed any 3rd party packages - ie outside the pfsense repo?
-
@Gertjan thanks. yeah, one of the first things I did was to change my administrator account password
I'm really curious about the root cause, I'm using Pfsense for many years now and I'm very positive about the solid secure design of pfsense, so I'm quite positive it had something to do with what I did, or alternatively one of the 3rd party packages.
@johnpoz, thank you too. the answer is NO, I didn't inherit my pfsense from anyone.
I suspect the ntopng package, I didn't login for a while and tried now to login with the "internet" user, but couldn't, nighter with my Administrator account.Thanks @Gertjan, luckily the internet"user is not root or even privilege, so I'm less worried then I was in my initial reaction.
Edit: found the login credentials for ntopng, it wasn't that!
-
@Phonix66 said in User called “internet”:
alternatively one of the 3rd party packages.
Again have you installed anything out side the repo as far as a package goes.. Like something available for freebsd, but not included in pfsense repo? Or there are some packages about that people have put together to install stuff, crowdstrike the latest example of this that I recall seeing.. But there are for sure others. I do recall a while back someone put together a way to install the unifi controller software on your pfsense, etc.
You have not played with any such sort of packages..
My guess is you at one point created it, maybe when testing out captive portal or something and forgot about it.
-
@johnpoz, sorry, missed the question, the answer is NO, absolutely nothing outside of the official packages from the repo, nighter any custom configuration.
-
Did the user have a home directory? Was there anything in it? Did it have a password?
-
@ebcdic I don't know where to check for the directory.
here are the details from the /etc/passwd:
internet:*:2000:65534::/home/internet:/sbin/nologinnologin would probably mean no home directory, am I right ?
-
@Phonix66 said in User called “internet”:
here are the details from the /etc/passwd:
internet:*:2000:65534::/home/internet:/sbin/nologinnologin would probably mean no home directory, am I right ?
The home directory is specified as /home/internet. /sbin/nologin should mean that the user can't log in.
2000/65534 are the user and group id you would get the first time you created a user through the user manager page. The directory /home/internet would then contain files called .hushlogin, .profile, .shrc, and .tcshrc.
I think the most likely explanation is that at some point you inadvertently created the user yourself, perhaps mistaking the page you were on in the user interface.
-
@Phonix66 Possibly an OpenVPN roadwarrior account you set up at some point.
Ted
-
@tedquade I guess it could be the case. actually I don't have any idea since the PFsense is installed for quite a while now.
I'll just remove the stale user and I have changed the admin password already.
So I guess that ok. I'll keep an eye on the users for a while, just to make sure.Thanks everyone, really appreciate that.
-
@Phonix66 said in User called “internet”:
I suspect the ntopng package, I didn't login for a while and tried now to login with the "internet" user, but couldn't, nighter with my Administrator account.
The ntopng package does not create such a user. What made you suspect it?
[Edit: You can ignore this -- I just saw that you subsequently determined that it wasn't ntopng]